APTMembers
APT

A 2010 Worm Still Trips a Live Tofsee Fingerprint — and Now It's Hauling a Miner

A Sality-lineage dropper first seen in mid-2010 still triggers a live malicious-JA3 detection tied to Tofsee infrastructure. In the same late-September indicator set it surfaces alongside a matched XMRig mining kit and two low-detection image-disguised payloads, suggesting a fifteen-year-old worm repurposed as delivery plumbing for commodity cryptomining.

Sep 28, 2026, 14:28 (UTC+9)Last seenSep 28, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC38RegionsUS

A Sality-lineage dropper that first surfaced in mid-2010 is still active enough to trip a live malicious-JA3 detection tied to Tofsee command-and-control infrastructure, and in the same indicator set it turns up alongside a matched XMRig mining kit — an executable and its configuration file staged through identical randomized-hex Temp folders — plus two low-detection payloads disguised as image files.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence